Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Web Security TippsNew manual calculation setting in Google Sheets(21.09.2026 um 20:54 Uhr)
Videos & KonferenzenTechquickie: The Steam Frame Shouldn't Work - Here's Why It Does(21.09.2026 um 21:17 Uhr)
Sichere ProgrammierungHow to Build a Production-Ready iOS App With AI-Generated Code(21.09.2026 um 21:00 Uhr)
Sichere ProgrammierungAfriex Integrations: Sandbox, Idempotency, and Webhook Simulation(21.09.2026 um 21:50 Uhr)
Sichere ProgrammierungBridging Local and Cloud Databases for Centralized Data Management(21.09.2026 um 21:51 Uhr)
Web Security TippsNew manual calculation setting in Google Sheets(21.09.2026 um 20:54 Uhr)
Videos & KonferenzenTechquickie: The Steam Frame Shouldn't Work - Here's Why It Does(21.09.2026 um 21:17 Uhr)
Sichere ProgrammierungHow to Build a Production-Ready iOS App With AI-Generated Code(21.09.2026 um 21:00 Uhr)
Sichere ProgrammierungAfriex Integrations: Sandbox, Idempotency, and Webhook Simulation(21.09.2026 um 21:50 Uhr)
Sichere ProgrammierungBridging Local and Cloud Databases for Centralized Data Management(21.09.2026 um 21:51 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

4,407 Rockwell PLCs Sit on the Public Internet, 22 in Cities Hit by Water Utility Attacks

TL;DR what: Forescout's August 3 scan found 4,407 internet-facing Rockwell PLCs worldwide, including 22 in US cities where water utilities reported attacks since July 27. Forescout scanned the internet on August 3 and counted 4,407…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




TL;DR





  • what: Forescout's August 3 scan found 4,407 internet-facing Rockwell PLCs worldwide, including 22 in US cities where water utilities reported attacks since July 27.



Forescout scanned the internet on August 3 and counted 4,407 exposed Rockwell Automation programmable logic controllers. 2,844 of them are in the United States. Twenty-two sit in cities where water utilities have reported cyberattacks since July 27, and 19 of those 22 ride the same mobile carrier network. Forescout could not confirm that any of the 4,407 were compromised, and the number counts controllers, not utilities or victims.



The part that should change your Monday: the effects described publicly in those water incidents did not require a vulnerability exploit. Attackers changed IP addresses and set passwords on controllers that were already reachable from the internet. Operators lost visibility, and in some cases control, of connected equipment. No CVE, no memory corruption, no zero-day. Just a device answering unauthenticated requests on a routable address.






What the exposure actually looks like



The reachable surface is EtherNet/IP on TCP port 44818. Depending on device configuration, an unauthenticated connection to that port lets an attacker identify the controller (vendor, product code, firmware revision, sometimes the project name) or write settings to it. That identification step is what makes mass scanning viable: an attacker does not need to guess what they hit, the device tells them.



Two independent snapshots agree on the scale. A July 30 Censys pull found 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts. Forescout's August 3 pull found 4,407. Different platforms, different queries, different days, so the figures are not directly comparable, but both clear 4,100. Forescout's historical series puts the June 2026 low at 4,169, down 47% from 7,814 in March 2020. Six years of ICS security advocacy cut the exposed population roughly in half and then flattened out.



Device breakdown from Forescout's results:




  • MicroLogix 1400: 50% of exposed controllers

  • MicroLogix 1100: 8% of exposed controllers

  • Both families were named specifically in the FBI and EPA advisory

  • The MicroLogix 1100 was discontinued by Rockwell on April 30, 2022, so a meaningful slice of this population is running end-of-life hardware






The cellular modem is the real attack surface



More than 70% of the US-based exposed controllers are on large mobile carrier networks. Censys attributed 59% of its 4,148 hosts to Verizon Business, AT&T Mobility, and T-Mobile USA. This is the classic small-utility remote-site pattern: a lift station or a well house with no fiber, a cellular router dropped in for SCADA polling and remote troubleshooting, and a public IP handed out by the carrier with nothing filtering inbound traffic.



Nineteen of the 22 controllers found in affected cities were on the same carrier network. That clustering matters more than the raw count. It suggests a shared integrator, a shared modem deployment template, or a shared APN configuration, and the FBI warned explicitly that similar third-party network setups may let attackers repeat a successful compromise across every customer sharing the vulnerable configuration. One integrator's default becomes a target list.




Federal guidance, in one line — The FBI and EPA recommend strong authentication, current firmware, and logging on cellular modems, with remote access isolated behind a private APN, a VPN, or an equivalent architecture. If your remote sites answer on a public carrier IP today, a private APN from the same carrier is usually a support ticket, not a capital project.







CVE-2017-16740 is a footnote, not the story



Forescout found that 19 of the 22 controllers in affected cities ran firmware susceptible to CVE-2017-16740, a Modbus TCP buffer overflow rated 8.6 by Rockwell. It affects MicroLogix 1400 Series B and C on firmware revision 21.002 and earlier, and Rockwell fixed it in revision 21.003. That patch has been available since 2017.



Two caveats keep this from being the headline. Exploitation requires Modbus TCP to be enabled, which Forescout could not verify on those hosts. And nothing in the reported attacker behavior needed the flaw. Forescout's own framing is the right one: firmware updates fix specific bugs but do not make direct public exposure of a PLC acceptable. Patch to 21.003 because nine-year-old known-vulnerable firmware on a control device is indefensible, not because it closes this campaign.






Recovery if you are already locked out



Rockwell advisory SD1790 covers the specific scenario operators are hitting: an attacker set a password on the controller and the owner can no longer connect. The procedure resets a MicroLogix 1400 or 1100 to factory defaults, after which you redownload a known-good project file. SD1790 carries no CVE because it is recovery guidance, not a vulnerability disclosure.




⚠️ The recovery path assumes a backup you may not have — Factory reset wipes the controller logic. SD1790 only works if you hold a current offline copy of the project file. The FBI reported that at least one victim discovered modified PLC project files after noticing ladder logic discrepancies across several sites, which means the on-device copy cannot be trusted as your restore source. Pull and hash offline copies of every controller program now, before you need them.







Open questions the advisories do not answer



Neither the government alerts nor Forescout's analysis explains how attackers found, selected, or initially accessed their targets. No agency has attributed the campaign. Even the scope is unsettled: the FBI and EPA July 30 public service announcement covers utilities in at least seven states, and as of August 6 the FBI page still says seven while Forescout's writeup describes the announcement as confirming at least 12. Treat the state count as unresolved, not as a bound on who is affected.






Do this week




  • Inventory every controller with a public IP. Search your carrier bills and modem management portals for static public addressing, not just your firewall rules.

  • Confirm whether TCP/44818 is reachable from outside. Test from an external host, not from the plant network.

  • Move remote sites to a private APN or force all SCADA traffic through a VPN terminating inside your network. Nothing on a control network should answer an unsolicited inbound connection.

  • Update MicroLogix 1400 Series B and C to firmware revision 21.003 or later, and disable Modbus TCP if you are not using it.

  • Build a replacement plan for MicroLogix 1100 units. The line has been discontinued since April 2022 and will not receive further fixes.

  • Export, store offline, and hash every PLC project file. Compare ladder logic across sites that should be identical.

  • Enable and centralize logging on cellular modems and controllers so an IP change or password set is something you detect rather than something an operator reports.



The 4,407 number will move with the next scan. The underlying condition will not, until someone takes the controllers off the public internet.






Originally published on RedEye Threat Intelligence.

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94497 | jshERP through 3.6 fails to validate object ownership in by-id info, upd…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick